A short, honest page for security, legal and procurement teams. Every artefact below is downloadable today; every claim points at a file you can read or a control you can exercise. No fabricated certifications, no nine-fives we can't measure, no logos we don't have. For the architectural argument and per-framework status, see the Trust Center and Compliance.
Enterprise procurement, custom MSA edits, volume-pricing requests, EU invoice billing and self-hosted licensing all route to one address. Median first response is one business day, quoted against your purchase decision date, not a marketing wishlist.
All of these are linked publicly — no NDA required for the templates. Counter-signed copies (DPA) are returned within two business days of an enterprise request.
Three shapes of the same product. Pick the one that fits your data-residency constraints and your operations team's appetite. The privacy design — values the detectors identify are tokenised on the customer side before the request is sent — is the same in all three. A value the detectors miss is sent as written.
Instead of adding the SDK to every app, run one central cloak-proxy on your own network — a server or container you control — and route all your apps through it (change one base_url). PII is tokenised on that proxy, inside your perimeter; the CloakAPI gateway receives the tokenised bytes. One place to configure detectors and privacy tiers, one place to update, every app protected.
None of this is gated behind an "Enterprise plan": every account pays the same flat rates. Where a capability is not generally available yet, the item says so.
webhook.test event is sent today, the other event types are reserved.While the beta lasts, CloakAPI has no service level agreement: /legal/sla is the binding text, and it sets no uptime target and no service credits. Below is how support works today and what we measure, with no inflated "five nines" claim that we can't measure.
How uptime is defined and measured is documented at /legal/sla (sections 2 and 8); live status is at status.cloakapi.io. Where this page and /legal/sla differ, /legal/sla is the binding text.
A short, predictable path from first contact to signed contract. Median time-to-signature for the last few enterprise deals has been three to six weeks, gated almost entirely on your security review.
Email enterprise@cloakapi.io with a one-line description of your use case and rough volume (requests/month or seats). You'll get a custom quote within two business days. List pricing — three flat gateway rates, no plan tiers or per-seat charges on the API — is on /pricing.
Custom MSA available; redlines welcome. DPA counter-signed within two business days of an enterprise request. Order forms are short — one schedule per environment, one per region.
Bank transfer and invoice billing in USD for annual orders above $25,000. Card and Stripe-tokenised payment for smaller commitments. Net-30 standard; net-60 on enterprise terms.
CAIQ-lite, SIG-lite, custom questionnaires, audit-letter requests and architecture reviews all go through trust@. Median turnaround on a completed CAIQ: three business days.
Most enterprise vendors hand you a marketing PDF. CloakAPI hands you verification tools. Gateway responses can carry a signed receipt that an auditor can check offline when one is issued. The JSONL transparency feed shows the latest published tenant seed state, not receipt events or the full seed-rotation history. A separate Merkle API exposes proofs for recorded content-free events; leaf writes are best-effort, so these surfaces do not prove that every change was recorded.
OpenReceipt: receipts use ECDSA P-256 / SHA-256 when they are issued, and can be hash-chained. The independent verifier at signedreceipts.org/verifier requires no CloakAPI account and does not send the receipt to us; it fetches our public keys and reports a pass/fail count (no receipt content) to api.cloakapi.io.
Per-tenant JSONL feed of the latest published seed state for tenants that turn transparency on (off by default), not the full rotation history. The response carries a Gateway HMAC-SHA256 value, not an ES256 receipt signature. A separate Merkle API exposes content-free leaves, tree heads and inclusion/consistency proofs for recorded events. Leaf writes are best-effort; without a checkpoint held outside the Gateway, these surfaces cannot prove that every rotation was recorded or that the full history was not rewritten.
GET https://api.cloakapi.io/v1/transparency/seeds.jsonl